This Privacy Policy describes how your personal data (“Personal Data”) is collected, used, and shared when you visit or make a purchase from www.luu-dan.com (the "Site" or “Website”). LU’U DAN takes your privacy very seriously and we do our best to adhere to the highest standards of data protection.

 

 

Data Collection

 

Personal Data that we may collect about you, and the reasons why we process it, include:

 

Type of Personal Data

Why we collect it

Legal basis

Name, Surname

Email address

Password

Customer ID

Order History

Shipping address

Delivery preferences

Financial information

Account details

Enabling you to create your account

Managing your account and personal preferences

Processing and shipping your orders

Enabling you to access your order history with us at all times

Providing you with customer service as may be required

Contractual necessity

Name, Surname

Customer ID

Order History

Shipping address

Financial information

Order number

Documenting transactions you made on our website

Our legitimate interests in order to protect LU’U DAN's business and legal rights

Name, Surname

Email address

Email preferences

Shopping preferences

Customer ID

Providing you with exclusive email updates, promotions, and notifications including information about our products or services

Your consent (unless a legal exception applies)

Name, Surname

Email address

Your inquiry and your inquiry history

Processing and responding to any inquiry that you may address to us

Contractual necessity

Name, Surname

Email address

Order History

Financial information

Account details

Prevention of fraud

Legal obligation

Name, Surname

Email address

Password

Customer ID

Account details

Administering and maintaining our web platform

Our legitimate interests in order to offer, maintain and improve our platform

IP address

Account details

Shopping preferences

Data analytics, statistics and audience measurement

Our legitimate interests in order to understand how our website is being used and to help us customise and measure the audience on our website

 

2 Please note that the information you provide on our Website may be necessary for contractual purposes and for us to comply with our legal obligations. Without such information, we may not be able to process your order or to answer your queries.

 

3 We may also collect certain information automatically from your device. Specifically, the information we collect automatically may include information like your IP address, device type, unique device identification numbers, browser-type, broad geographic location (e.g. country or city-level location) and other technical information. We may also collect information about how your device has interacted with our Website, including the pages accessed and links clicked.

 

4 Collecting this information enables us to better understand the visitors who come to our Website, where they come from, and what content on our Website is of interest to them. We use this information for our internal analytics purposes and to improve the quality and relevance of our Website to our visitors.

 

5 Pursuant to the General Data Protection Regulation (“GDPR”), if you are a resident of the European Economic Area (“EEA”), we process your Personal Data in accordance with the legal basis as explained above.

 

 

Sharing your Personal Data

 

We may disclose your Personal Data to the following categories of recipients:

 

(a) to our group companies for purposes consistent with this Privacy Policy, and in particular, so that they may contact you regarding products and services that may be of interest to you where you have given your consent. We take precautions to allow access to Personal Data only to those staff members who have a legitimate business need for access and with a contractual prohibition of using the Personal Data for any other purpose. Our group companies include: Atallah Group Inc. d.b.a. SSENSE, Atallah Group Limited, Atallah Hong Kong Limited, Atallah Group US Inc., GAI Services PTY Limited, Atallah International Inc.

 

(b) to our third party vendors, services providers and partners who provide data processing services to us, or who otherwise process Personal Data for purposes that are described in this Policy or notified to you when we collect your Personal Data. This may include disclosures to third party vendors and other service providers we use in connection with the services they provide to us, including to support us in areas such as IT platform management or support services, infrastructure and application services, marketing, data analytics. Our third party vendors, service providers and partners include, without being limited to: our logistics provider(s), Shopify (https://www.shopify.com/legal/privacy), Paypal Express, Facebook, Klaviyo, Invoice Hero and PluginHive.

 

(c) to any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person;

 

(d) to our auditors, advisors, legal representatives and similar agents in connection with the advisory services they provide to us for legitimate business purposes and under contractual prohibition of using the Personal Data for any other purpose;

 

(e) to a potential buyer (and its agents and advisers) in connection with any proposed purchase, merger or acquisition of any part of our business, provided that we inform the buyer it must use your Personal Data only for the purposes disclosed in this Notice;

 

(f) to any other person if you have provided your prior consent to the disclosure.

 

 

Data storage, retention and deletion

 

1 The Personal Data we collect from you is stored in our servers located around the world.

  1. We retain Personal Data we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements).
  2. When we have no ongoing legitimate business need to process your Personal Data, we will either delete or anonymise it or, if this is not possible (for example, because your Personal Data has been stored in backup archives), then we will securely store your Personal Data and isolate it from any further processing until deletion is possible.

 

 

International transfers of Personal Data

  

1 Your Personal Data may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different to the laws of your country.

  

2 Specifically, our Website servers are located around the world, and our group companies and third party service providers and partners operate around the world. This means that when we collect your Personal Data we may process it in any of these countries.

 

3 However, we have taken appropriate safeguards to require that your Personal Data will remain protected in accordance with this Policy. When transferring your Personal Data to Canada, we rely on the EU Commission's adequacy decision 2002/2/EC available here. When transferring your Personal Data to the United States, we rely on the EU Commission's EU-US Privacy Shield decision (available here) if the recipient is appropriately certified. In all other cases, we only transfer or make your Personal Data available to other entities of the group of companies, to which LU’U DAN belongs, or to our third party services providers in third countries where such transfer is necessary for the performance of a contract between you and LU’U DAN or the implementation of pre-contractual measures.

 

 

Automatic decision-making

 

If you are a resident of the EEA, you have the right to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects you.

 

We do not engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.

 

Our processor Shopify uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you.

 

Services that include elements of automated decision-making include:

 

--- Temporary blacklist of IP addresses associated with repeated failed transactions. This blacklist persists for a small number of hours.

 

---Temporary blacklist of credit cards associated with blacklisted IP addresses. This blacklist persists for a small number of days.

 

 

Selling Personal Data

 

Our Site does not sell Personal Data, as defined by the California Consumer Privacy Act of 2018 (“CCPA”).

 

 

Your rights


You have the following data protection rights:

 

1 If you wish to access, correct, update or request deletion of your Personal Data, you can do so at any time by contacting us by email at: shop@luu-dan.com

 

2 In addition, in certain circumstances, as stipulated in the applicable data protection legislation, you can object to processing of your Personal Data, ask us to restrict processing of your Personal Data or request portability of your Personal Data. Again, you can exercise these rights by contacting us using the contact details mentioned above.

 

3 If we have collected and processed your Personal Data with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your Personal Data conducted in reliance on lawful processing grounds other than consent.

 

4 If you have a complaint or concern about how we are processing your Personal Data then we will endeavour to address such concern(s). If you feel we have not sufficiently addressed your complaint or concern, you have the right to complain to a data protection authority about our collection and use of your Personal Data.  For more information, please contact your local data protection authority. (Contact details for data protection authorities in the European Economic Area, Switzerland and certain non-European countries (including the US and Canada) are available here.)

 

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.

 

 

GDPR

 

If you are a resident of EEA, kindly note that your Personal Data will be initially processed in Ireland and then will be transferred outside of Europe for storage and further processing, including to Canada and the United States. For more information on how data transfers comply with the GDPR, see Shopify’s GDPR Whitepaper: https://help.shopify.com/en/manual/your-account/privacy/GDPR.

 

 

CCPA

 

If you are a resident of California, you have the right to access the Personal Data we hold about you (also known as the ‘Right to Know’), to port it to a new service, and to ask that your Personal Data be corrected, updated, or erased. If you would like to exercise these rights, please contact us through the contact information above. 

 

If you would like to designate an authorized agent to submit these requests on your behalf, please contact us at the address above.

 

 

Minors

 

The Services we provide on this Website are not intended for individuals below the age of majority in your jurisdiction. If you are a minor in your jurisdiction, please do not use or register on this Website.

 

 

Linking to other websites

 

The Website may contain hyperlinks to websites owned and operated by third parties. These websites have their own privacy policies and we urge you to review them. They will govern the use of Personal Data you submit whilst visiting these websites. We do not accept any responsibility or liability for the privacy practices of such third party websites and your use of such websites is at your own risk.